CVE-2011-2911: Buffer Overflow
Integer overflow in the CSoundFile::ReadWav function in src/loadwav.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted WAV file, which triggers a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2911?
CVE-2011-2911 has been assessed as a high severity vulnerability due to its potential for causing denial of service and remote code execution.
How do I fix CVE-2011-2911?
To fix CVE-2011-2911, upgrade libmodplug to version 0.8.8.4 or later, which contains the necessary security patches.
What types of attacks can CVE-2011-2911 facilitate?
CVE-2011-2911 can facilitate attacks that lead to denial of service and potentially allow attackers to execute arbitrary code by exploiting crafted WAV files.
Which versions of libmodplug are affected by CVE-2011-2911?
CVE-2011-2911 affects libmodplug versions prior to 0.8.8.4, including 0.8.5, 0.8.7, and all versions up to and including 0.8.8.3.
What is the impact of CVE-2011-2911 on systems using affected versions?
Systems using affected versions of libmodplug may experience crashes and could be compromised, resulting in unauthorized code execution.